Cyber Resilience
← All news
Confirmed

Rently Smart Home

Our takeCISA reports active exploitation of an insufficiently protected credentials flaw (CVSS 8.1) in Rently Smart Home <=20.1.0 that can expose sensitive data and override permissions. Update to a fixed version now.
Sources (1)
What this means for you — Security leader:Update Rently Smart Home to a version newer than 20.1.0; CISA reports active exploitation of insufficiently protected credentials that can expose sensitive data and override permissions.
What this means for you — Lean IT orgs:If you use Rently Smart Home for property access, update it immediately to a version above 20.1.0; most lean teams without this product can ignore this advisory.
What this means for you — MSP:Check client environments for any use of Rently Smart Home <=20.1.0 and update it; CISA confirms active exploitation of insufficiently protected credentials.
What this means for you — Researcher:CISA ICSA-26-237-01 details CVE in Rently Smart Home <=20.1.0 (insufficiently protected credentials, CVSS 8.1) confirmed exploited in the wild; successful attacks allow sensitive data access and permission overrides.